Question

Winlogon virus? Blue Screen - c000021a

Asked by: srhsxbx

Hey guys I'm running Xp home and I out of nowhere on it's next boot there was the blue screen.
"STOP: c000021a {Fatal System Error}
The Windows Logon Process system process terminated unexpectedly with a status of 0x00000000 (0x00000000 0x00000000).
The system has been shut down"

Now safe mode alone works. I've tried removing the battery and memory. But it still looks like it didn't help much although there was one time when It worked properly.. Strange... So anyways that one time when I was able to get it, I ran AVG and I found over 100 viruses/ threats. One of the first listing winlogon.exe
Now after the scan I rebooted and it was back to first base.  So then through safe mode I used AVG  and I ran another scan and it looks like it found it again. But no luck on the next reboot. My guess is I have a virus in winlogon an that's why it can't boot after the windows loading screen. As you can see I'm not the best at removing viruses manually, and I would really appreciate the help. Thx.

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-03-04 at 20:00:48ID24200301
Topics

Anti-Virus

,

Windows XP Operating System

Participating Experts
7
Points
500
Comments
32

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. inoculan and winlogon
    Hi i just found the backdoor Subseven 2.2 server virus. I'm doing a full scan of the HD. During the first part of the scanning everything runs smoothly. I'm also runing task manager to see if no weird programs are running, but only inocuLAN.exe used cpu time. Once the sc...
  2. Winlogon problems.
    Hi Experts. I had a problem with Windows NT4.0 workstation. After I ran repair disk from the floppy, CD-ROM and finished the repair processes. The Windows start-up, pass the blue screen then go blank and hang there before go to winlogon. I restart computer again and this tim...
  3. Application popup: Winlogon generic control dialog: winlo…
    Having deployed the lastest security fixes on our test group, we have had several machines rebooting during the day with no indication. I assume, machines that had their screensaver activated received the message : Application popup: Winlogon generic control dialog: winlogo...
  4. Winlogon trying to access Internet
    I have a problem with Winlogon trying to access the Internet - my firewall stops it but how do I remove the problem? Thanks Colin Northway
  5. Winlogon error, then bluescreen at every restart
    My laptop got hit with malware called "BraveSentry". I have run all the utilities to remove it, and it is completely gone. What is left, now, is a persistent winlogon error. Whenever I shutdown/restart windows, I get the following errors in this screenshot: www.s...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: chakkoPosted on 2009-03-04 at 20:16:07ID: 23802555

The fastest and easiest way to get up and running would be to try and use the System Restore tool and restore your PC to a point before the problem occurred.

System Restore tool can be at:  Start - Programs - Accessories - System Tools -> System Restore

If you have a Restore Point saved you can restore it, then do another Full Scan of your system.

Also, AVG is not enough to find/remove any threats on your PC.  I recommend you download and try using these also.

Spybot Search and Destroy
Combofix
Malwarebytes Anti-malware


 

by: travisgishPosted on 2009-03-04 at 20:55:02ID: 23802671

I have just ran into that same thing on a customers PC. We had to pull the drive and scan it in another machine. But even even then we had to do a windows repair. If you can I would just try to backup all your data and do a fresh install and save yourself a lot of trouble.

 

by: orangutangPosted on 2009-03-04 at 21:08:38ID: 23802721

 

by: srhsxbxPosted on 2009-03-04 at 21:58:19ID: 23802902

Good news is I DO have restore points. Bad news is once I'm on the "Confirm Restore Point Selection" screen the Next button is non responsive and I can't get anywhere. Also I am in safe mode since I got no other option and I can't give you my HJT file since I have no internet access.. It stinks. Any ideas?

 

by: orangutangPosted on 2009-03-04 at 22:04:37ID: 23802918

You can download the files with another computer and put them on a CD or something and put them on that computer.

 

by: chakkoPosted on 2009-03-04 at 22:39:09ID: 23803021


Just in case, here is some help on using the System Restore
http://www.bleepingcomputer.com/tutorials/tutorial56.html

Note: go down to about the middle of the page. Do Not remove the checkbox to disable System Restore - the article says it will delete the saved points from your computer.


Not sure why you cannot do the system restore but found this on the internet.
Some other people had problems with system restore.  If you're comfortable with regedit, you can check the values and see if something is different.

http://www.kellys-korner-xp.com/regs_edits/sysrestoreenable.reg


 

by: JonveePosted on 2009-03-04 at 23:52:58ID: 23803302

From all the comments and symptoms above, the reason for System Restore not working is probably because the machine is still heavily infected.

Suggest you re-try downloading ComboFix:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Can you access another computer to download ComboFix, and burn it to a CD or other media ?

If you can, before using ComboFix, please disable any realtime Anti-virus, Anti-spyware, Shields, etc. that you may have running, and remember to re-enable them later, upon completion.

Also it may be necessary to rename ComboFix (to ComboFix5 for example) before saving it to your desktop.  If you have difficulties downloading it, try downloading to another machine, then into a USB memory stick (or equivalent).  Rename it, and connect to the problematic machine.

Double click "combofix.exe" and follow the prompts.
When it's finished it will have produced a Logfile, probably at C:\ComboFix.txt.
You could post that log together with a HijackThis log, in a reply for us.
Please do not mouseclick Combofix's window while it is running, because it may stall.  It is absolutely normal for you to see a blue screen with flashing cursor, and this can last for up to 30 mins.  Just let it run.

It works well in normal mode or safe mode.

An alternative would be to remove the infected HD, connect it as 'slave' in another machine, then run ComboFix from the new machine.

 

by: nobusPosted on 2009-03-05 at 03:50:22ID: 23804523

can you post the minidump for analysis?   rename it to***.txt

 

by: srhsxbxPosted on 2009-03-05 at 05:47:09ID: 23805313

It's pretty strange I'm looking in the minidump folder and the latest file was created back on 12/5/08. Will this work or am I do you think I have different settings wrong. I will try using ComboFix as soon as I have access. Thx.

 

by: nobusPosted on 2009-03-05 at 07:44:04ID: 23806645

maybe your system is set no to make them. verify in device manager> advanced tab>system restart settings

 

by: JonveePosted on 2009-03-05 at 09:29:27ID: 23807966


You could look for the minidump(s) in both these places>
c:\windows\minidump\    
or  %systemroot%\minidump\

Can you paste the latest dump(s) in the "Attach Code Snippet" box

It's preferable to have at least three if you can locate any, then you could zip them before attaching.

If you see no minidump>
Enable Minidump's in Windows XP:
http://www.cakewalk.com/Support/ProblemReporter/minidump.asp

Also try My Computer>Properties>Advanced>Startup & Recovery.
Are the boxes under 'Settings' checked, & 'small memory dump' selected?
[Or, see if you have a Dump Check Utility or a related Dumpchk.exe file, there could be a minidump located there].

Absence of Minidumps can be due to deteriorating motherboard capacitors, or unstable/flakey power supply.

 

by: DavisMcCarnPosted on 2009-03-06 at 04:05:36ID: 23815740

I wish you had listed the viruses found by AVG; but, from your description can almost guaranty you have VIRUT/VIRUX/SCRIBBLEA.  Since it infects every executable on your system and downloads several other secobdary infestations, the only sure fix is to use the factory recovery option, either from your CD's or by using the function key option before booting.

Be warned that you need to backup any files you don't want to lose (Email, pictures, music, documents, taxes, etc) beforehand and will need to install all of your software again.

Even if you got a system restore to work, it would infect those files during the reboot.

Here is another thread: http://www.experts-exchange.com/Security/Vulnerabilities/Q_24126536.html

 

by: srhsxbxPosted on 2009-03-07 at 20:18:35ID: 23827941

hey guys sorry for the late response. I work every single day and the only time i get to work on it is after work, and it just gets really tiring so it took me forever to get this for you guys. Its really crazy...  i managed to run combo fix on safe mode. I can now get past to the desktop in standard startup, but after about 3 min i get a memory dump? Looks like i still owe you a minidump log... thats what i will be working on. Anyways.. it looks like my computer is really infected. So heres some logs i attached.. HJT, ComboFix, and i somehow managed to get an AVG log which was the first one. I appreciate the help guys.. thx.

 

by: orangutangPosted on 2009-03-07 at 21:00:06ID: 23828026

Also, did you run Malwarebytes? These items are suspicious in your HijackThis log:

O2 - BHO: C:\WINDOWS\system32\gwsh3b8iefd.dll - {C5AF42A3-94F3-42BD-F634-3604832C897D} - C:\WINDOWS\system32\gwsh3b8iefd.dll (file missing)
O4 - HKLM\..\Run: [jsg8jfgfdfhfhf] C:\WINDOWS\TEMP\winlognn.exe
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKLM\..\Run: [Explorer] C:\WINDOWS\system32\msrstart.exe
O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKLM\..\Run: [svchost.exe] "C:\WINDOWS\system32\3361\svchost.exe"
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [CPMaba12e3a] Rundll32.exe "c:\windows\system32\mufazuri.dll",a
O4 - HKLM\..\RunOnce: [svchost.exe] "C:\WINDOWS\system32\3361\svchost.exe"
O4 - HKCU\..\Run: [comidle]  "C:\Documents and Settings\Doina\Application Data\comidle\comidle.exe" 61A847B5BBF728173599284503996897C881250221C8670836AC4FA7C8833201749139
O4 - HKCU\..\Run: [jsg8jfgfdfhfhf] C:\WINDOWS\TEMP\winlognn.exe
O4 - HKCU\..\Run: [efk8muzw08jrth580cmws2npa0oxpmo3ua0zbgu] C:\DOCUME~1\Doina\LOCALS~1\Temp\kbrpy9sq.exe
O4 - HKCU\..\Run: [sh9qg2qywi77xkp1x] C:\DOCUME~1\Doina\LOCALS~1\Temp\c3jxmprsljgyg.exe
O4 - HKCU\..\Run: [vp6m9tyqvcpu31gg5pfwqnyjzgxd5s69z0eg7karw5ew5] C:\DOCUME~1\Doina\LOCALS~1\Temp\zx9nzuel4z.exe
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\Doina\reader_s.exe
O4 - HKCU\..\Run: [v5ddnnvynttm1l7ok] C:\DOCUME~1\Doina\LOCALS~1\Temp\s0bjfnpes68.exe
O4 - HKCU\..\Run: [vn2lzachu2l6zz6g9v] C:\DOCUME~1\Doina\LOCALS~1\Temp\khaxqv.exe
O4 - HKCU\..\Run: [bvtbmn0k0tiaqeb4e5sboy738btbg21g1fp01yr] C:\DOCUME~1\Doina\LOCALS~1\Temp\v4d6o2bv.exe
O4 - HKCU\..\Run: [lzhvt1aivyqyskuvyqv71njdwn6] C:\DOCUME~1\Doina\LOCALS~1\Temp\jsl9uv.exe
O4 - HKLM\..\Policies\Explorer\Run: [xccinit] C:\WINDOWS\system32\inf\rundll33.exe C:\WINDOWS\xccdf16_090131a.dll xccd16
O4 - HKLM\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe
O4 - HKUS\S-1-5-18\..\Run: [jsg8jfgfdfhfhf] C:\WINDOWS\TEMP\winlognn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [c3ef60fn00uqsvyukxsr] C:\WINDOWS\TEMP\uhjtax.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [kn8twuae71kfelf39puhjfhe4ucix] C:\WINDOWS\TEMP\m31rbmx5.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [tcsu3fvi8k9ig1ulo11xlwgp1g9i24puryjlabtv6lgzfxf] C:\WINDOWS\TEMP\boph7e.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [reader_s] C:\Documents and Settings\Doina\reader_s.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [comidle]  "C:\Documents and Settings\Doina\Application Data\comidle\comidle.exe" 61A847B5BBF728103B9D3B466188719AB689201522886B092CBD44BD8689220221DD3257 (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ikxqedjgvt74hzx1cd8m99] C:\WINDOWS\TEMP\c6az0wy50z.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [kyuu1x56ysizqewgbnxwnjln89hld55n5d3ho60ku] C:\WINDOWS\TEMP\eg78awbfx9rr.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [tjbtafqs.exe] C:\WINDOWS\tjbtafqs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'Default user')
O10 - Unknown file in Winsock LSP: c:\windows\temp\ntdll64.dll
O10 - Unknown file in Winsock LSP: c:\windows\temp\ntdll64.dll
O20 - Winlogon Notify: yayvVOef - yayvVOef.dll (file missing)
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mufazuri.dll (file missing)
O22 - SharedTaskScheduler: har78w3uhewf8yurhefd - {C5AF42A3-94F3-42BD-F634-3604832C897D} - C:\WINDOWS\system32\gwsh3b8iefd.dll (file missing)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\mufazuri.dll (file missing)
O23 - Service: afisicx - Unknown owner - C:\WINDOWS\system32\afisicx.exe (file missing)
O23 - Service: mabidwe - Unknown owner - C:\WINDOWS\system32\mabidwe.exe (file missing)
O23 - Service: sopidkc  Service (sopidkc) - Unknown owner - C:\WINDOWS\system32\sopidkc.exe

 

by: JonveePosted on 2009-03-08 at 00:56:25ID: 23828497

The machine was heavily infected & Combo has removed a lot.

From the HijackThis log there are signs of a Vundo infection.  With this infection the ComboFix log often shows bad entries that ComboFix was unable to remove, so it may yet be necessary to use its CFScript feature.

However, Housecall will find and remove a Vundo trojan, it's worth trying>
"Trend Micro's FREE online virus scanner":            
http://housecall.trendmicro.com/uk/
Ideal for scanning online, using "Safe Mode with networking".      

If unsuccessful try downloading VundoFix 7.0.6 >>
http://www.softpedia.com/get/Antivirus/VundoFix.shtml

To use VundoFix please follow the instructions written below>>

· Please download VundoFix.exe to your desktop.
· Double-click VundoFix.exe to run it.
· Put a check next to Run VundoFix as a task.
· You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
· When VundoFix re-opens, click the Scan for Vundo button.
· Once it's done scanning, click the Remove Vundo button.
· You will receive a prompt asking if you want to remove the files, click YES
· Once you click yes, your desktop will go blank as it starts removing Vundo.
· When completed, it will prompt that it will shutdown your computer, click OK.
· Turn your computer back on.

Another option is to follow that last suggestion with the Kaspersky free online virus scanner, which is a good way to find out if you have any viruses or spyware without having to uninstall your existing antivirus software>
http://www.kaspersky.co.uk/virusscanner

Does it still BSOD, and if you can reach normal mode are there any(or many?) infection symptoms ?

 

by: JonveePosted on 2009-03-08 at 01:54:14ID: 23828619

From the observed infections you could benefit from running other scanners, and as there's no single scanner that can remove all nasties, it's worth trying the following  ... i appreciate you have little spare time to troubleshoot this machine, but we're going to be around for a while.  

Superantispyware:                        
http://www.superantispyware.com/

If you have problems running any of the above, try the 'Stinger' which is a utility that cleans the system of viruses that block antivirus s/w.
http://vil.nai.com/vil/stinger/


Finally, if we find that we just cannot cleanup & fix all issues, it may be time to consider a clean install ... we're still a long way from that scenario, but just in case >

"Clean Install Windows XP":
http://www.michaelstevenstech.com/cleanxpinstall.html
Ok, i see you can reach the desktop!

From the observed infections you could benefit from running other scanners, and as there's no single scanner that can remove all nasties, it's worth trying the following  ... i appreciate you have little spare time to troubleshoot this machine, but we're going to be around for a while.  

Superantispyware:                        
http://www.superantispyware.com/

If you have problems running any of the above, try the 'Stinger' which is a utility that cleans the system of viruses that block antivirus s/w.
http://vil.nai.com/vil/stinger/


Finally, if we find that we just cannot cleanup & fix all issues, it may be time to consider a clean install ... we're still a long way from that scenario, but just in case >

"Clean Install Windows XP":
http://www.michaelstevenstech.com/cleanxpinstall.html

 

by: JonveePosted on 2009-03-08 at 01:57:21ID: 23828629

Sorry about the duplication, please read the post beginning at >>

Ok, i see you can reach the desktop!   ....

 

by: JonveePosted on 2009-03-08 at 08:33:58ID: 23829693

Two more very capable scanners you could run>>

BitDefender Free Online Virus Scan:
http://www.bitdefender.com/scan/licence.php
Ensure you tick AutoClean, under Scan Options

Panda ActiveScan:
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
Ensuring you tick Disinfect automatically, under Scan Options

From ComboFix log, note that there are still several malicious entries to be removed, here's one of them>
XCCEF090131.EXEMalicious Software:
http://www.prevx.com/filenames/X1300613496490119968-X1/XCCEF0901312EEXE.html


Then, if problems are still not resolved try running this ComboFix script on another Combo scan >>


1. Open Notepad.
2. Copy & paste all text between the lines below, into Notepad window:
=========================================================

File::
c:\windows\system32\d3d8caps.dat
c:\windows\system32\rtl60.bpl
c:\windows\system\xccef090131.exe
c:\windows\system32\pcistub.sys [?]


Folder::
c:\documents and settings\Doina\Application Data\comidle\comidle.exe

==================================================
3. Now Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt just created into ComboFix.exe. This will re-start ComboFix, & hopefully the problem is removed.
5. Finally, please attach the newComboFix logfile.

You may find the updated instructions useful>>
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

 

by: srhsxbxPosted on 2009-03-13 at 21:53:05ID: 23885458

Guys... horrible news...
So as i posted on my last thread.. i was able to get into my desktop... but now unfortunately when i came back from work one of the kids used the computer . So when i booted the computer... here it comes....

"windows could not start because the folllowing file is missing or corrupt:
System32\Drivers\Ntfs.sys

*Note: I cannot enter Safe Mode or anything else other than BIOS setup""
So it goes on telling me i can use system repair. Anyways i changed boot setings inserted my xp Cd. and now i was able to get into the cd, and it looked like system setup was working. After about 2-3 min of load time, the last step before loading windows setup was to load windows and thats where it comes:

STOP: 0x0000007E (0xC0000005, 0xF786B0BF, 0xF7CB7208, 0xF7CB6F08)

*** pci.sys - Address F786B0BF base at F7864000, DateStamp 3b7d855c

Im telling you guys.... this really stinks. I was thinking about re-formatting, but it looks like im out of luck since i can't even get into windows set-up on my cd. Could it be a memory problem since it says PCI? More problems after another... i'd really appreciate the help. Thanks guys.

 

by: travisgishPosted on 2009-03-13 at 22:03:47ID: 23885480

Doesn't sound like it. That's just saying that it cannot load the pci.sys driver. Chances are if you wipe it and do a fresh install it will run fine. That error can be caused by any number of things. Memory is just one of them, but with your recent troubles I would say it's not bad memory. Just a messed up windows install.

 

by: JonveePosted on 2009-03-14 at 00:03:45ID: 23885711

Info on Stop error  0x0000007E <
http://aumha.org/a/stop.htm

As you probably realise, to resolve the problem you need to replace the missing Ntfs.sys file, and do need to be able to use the XP CD >

"Missing or corrupt Ntfs.sys" error
http://support.microsoft.com/kb/822800

Looks like a clean install is your best bet, but again you need that CD > 
"Clean Install Windows XP":
http://www.michaelstevenstech.com/cleanxpinstall.html

 

by: nobusPosted on 2009-03-14 at 01:15:57ID: 23885828

it can also be bad hardware ; to check test if you can run from a live cd, like knoppix : www.knoppix.org

 

by: srhsxbxPosted on 2009-03-14 at 09:05:34ID: 23887505

The problem is I'm getting that error code while trying to start windows setup off of the cd which is holding me back from doing a fresh install.

 

by: nobusPosted on 2009-03-14 at 10:19:51ID: 23887718

try the knoppix cd ) it will show if you have bad hardware or not

 

by: DavisMcCarnPosted on 2009-03-14 at 12:03:29ID: 23888063

Your problem is that the SATA controller is set for AHCI mode and the easy answer is to enter the BIOS and change it to ATA or "Compatible" mode.  Either that or you need to download the Intel Storage Manager software, create a floppy disk (yes you will have to have a floppy drive available), then use the F6 option in Windows setup to install the drivers from the floppy.

Its really much easier to change the BIOS!

http://www.intel.com/support/chipsets/imsm/sb/cs-021736.htm

 

by: srhsxbxPosted on 2009-03-14 at 17:22:37ID: 23889253

On to the next problem.......
Good news is I'm passed the error!!! I streamlined a xp cd with sp3 on it.. But after clicking setup and then r for repair and on the next reboot it brought be into windows setup as if I'm reinstalling windows xp. Anyways it goes installing and as soon as it's at installing devices my USB devices are disabled. I get an error telling me my network adapter ha not passed the windows logo testing. Anyways my comp only has USB for mouse/ keyboard. And I can't clcik anything.
Note: USB works great until I get at re installing devices point in installation.

Note2: davismccarn... Thanks your solution worked! But here I am on another problem.  

 

by: srhsxbxPosted on 2009-03-14 at 17:33:15ID: 23889283

I don't have a oem disk. Do I need to find out what kind of driver I need and streamline it into another disk??

 

by: DavisMcCarnPosted on 2009-03-15 at 05:05:05ID: 23890741

What is the manufacturer and model of the computer?  We're into specifics so its needed.

Micro$oft, BTW, stopped certifying XP drivers when Vista was released so all newer drivers will give that "logo testing" error.  Say, yes, "continue anyway".

If the system has PS/2 ports, I would advise scrounging up a keyboard and mouse to plug into them until Windows is setup.

 

by: srhsxbxPosted on 2009-03-15 at 07:53:17ID: 23891580

Dell Dimension 9150
I would love to click ok but I'm stuck. No USB, so I have no mouse or keyboard. Also I have no PS/2 ports on my system :( . Like I said before the USB driver is disabled only when the windows setup gets to "installing devices".

Anyways I ordered a Oem backup disk hoping that I have all of the drivers on there for my computer and hopefully it can help.  

 

by: DavisMcCarnPosted on 2009-03-15 at 08:41:12ID: 23891777

If you have backed up everything you care about and have not changed the Hard Disk drive, CTRL-F11 at the Dell logo screen should launch the factory recovery.
http://support.dell.com/support/topics/global.aspx/support/dsn/document?c=us&cs=04&l=en&s=bsd&docid=3E48AE3870775D64E040A68F5B2877D4&journalid=651258DE7F881BC2E040AE0AB6E15A70&Query=&SystemID=&ServiceTag=&contenttype=&os=&component=&lang=&doclang=&toggle=&dl=

From your description, I am fairly sure you did not tell XP's setup to format the drive which is why it is finding uncertified drivers.  You should be able to get past it and be functional if you redo the installation and tell it to format the partition.

Go here and enter your service tag number to get everything there is on your computer:
http://support.dell.com/support/topics/global.aspx/support/product_support/en/product_support_central?~ck=ln&c=us&cs=04&l=en&lnki=0&s=bsd

 

by: nobusPosted on 2009-03-15 at 09:05:53ID: 23891885

i think you should run a repair install : http://www.michaelstevenstech.com/XPrepairinstall.htm      

 

by: bad3000Posted on 2009-12-29 at 18:46:18ID: 26142925

STOP: 0x0000007E (0xC0000005, 0xF786B0BF, 0xF7CB7208, 0xF7CB6F08)

*** pci.sys - Address F786B0BF base at F7864000, DateStamp 3b7d855c

It's a message when you boot with a WinXP CD without ServicePacks on a brand new computer, since HT and Dual Core processors you must boot with XP Boot CD with SP2 or later.

Just for add some knowledge to your thread.

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...